libarchive: do not extract unsafe symlinks unless $EXTRACT_UNSAFE_SYMLINKS=1
[oweals/busybox.git] / archival / unzip.c
1 /* vi: set sw=4 ts=4: */
2 /*
3  * Mini unzip implementation for busybox
4  *
5  * Copyright (C) 2004 by Ed Clark
6  *
7  * Loosely based on original busybox unzip applet by Laurence Anderson.
8  * All options and features should work in this version.
9  *
10  * Licensed under GPLv2 or later, see file LICENSE in this source tree.
11  */
12 /* For reference see
13  * http://www.pkware.com/company/standards/appnote/
14  * http://www.info-zip.org/pub/infozip/doc/appnote-iz-latest.zip
15  *
16  * TODO
17  * Zip64 + other methods
18  */
19 //config:config UNZIP
20 //config:       bool "unzip (24 kb)"
21 //config:       default y
22 //config:       help
23 //config:       unzip will list or extract files from a ZIP archive,
24 //config:       commonly found on DOS/WIN systems. The default behavior
25 //config:       (with no options) is to extract the archive into the
26 //config:       current directory.
27 //config:
28 //config:config FEATURE_UNZIP_CDF
29 //config:       bool "Read and use Central Directory data"
30 //config:       default y
31 //config:       depends on UNZIP
32 //config:       help
33 //config:       If you know that you only need to deal with simple
34 //config:       ZIP files without deleted/updated files, SFX archives etc,
35 //config:       you can reduce code size by unselecting this option.
36 //config:       To support less trivial ZIPs, say Y.
37 //config:
38 //config:config FEATURE_UNZIP_BZIP2
39 //config:       bool "Support compression method 12 (bzip2)"
40 //config:       default y
41 //config:       depends on FEATURE_UNZIP_CDF && DESKTOP
42 // FEATURE_UNZIP_CDF is needed, otherwise we can't find start of next file
43 // DESKTOP is needed to get back uncompressed length
44 //config:
45 //config:config FEATURE_UNZIP_LZMA
46 //config:       bool "Support compression method 14 (lzma)"
47 //config:       default y
48 //config:       depends on FEATURE_UNZIP_CDF && DESKTOP
49 //config:
50 //config:config FEATURE_UNZIP_XZ
51 //config:       bool "Support compression method 95 (xz)"
52 //config:       default y
53 //config:       depends on FEATURE_UNZIP_CDF && DESKTOP
54
55 //applet:IF_UNZIP(APPLET(unzip, BB_DIR_USR_BIN, BB_SUID_DROP))
56 //kbuild:lib-$(CONFIG_UNZIP) += unzip.o
57
58 //usage:#define unzip_trivial_usage
59 //usage:       "[-lnopq] FILE[.zip] [FILE]... [-x FILE...] [-d DIR]"
60 //usage:#define unzip_full_usage "\n\n"
61 //usage:       "Extract FILEs from ZIP archive\n"
62 //usage:     "\n        -l      List contents (with -q for short form)"
63 //usage:     "\n        -n      Never overwrite files (default: ask)"
64 //usage:     "\n        -o      Overwrite"
65 //usage:     "\n        -j      Do not restore paths"
66 //usage:     "\n        -p      Print to stdout"
67 //usage:     "\n        -q      Quiet"
68 //usage:     "\n        -x FILE Exclude FILEs"
69 //usage:     "\n        -d DIR  Extract into DIR"
70
71 #include "libbb.h"
72 #include "bb_archive.h"
73
74 #if 0
75 # define dbg(...) bb_error_msg(__VA_ARGS__)
76 #else
77 # define dbg(...) ((void)0)
78 #endif
79
80 enum {
81 #if BB_BIG_ENDIAN
82         ZIP_FILEHEADER_MAGIC = 0x504b0304,
83         ZIP_CDF_MAGIC        = 0x504b0102, /* CDF item */
84         ZIP_CDE_MAGIC        = 0x504b0506, /* End of CDF */
85         ZIP_DD_MAGIC         = 0x504b0708,
86 #else
87         ZIP_FILEHEADER_MAGIC = 0x04034b50,
88         ZIP_CDF_MAGIC        = 0x02014b50,
89         ZIP_CDE_MAGIC        = 0x06054b50,
90         ZIP_DD_MAGIC         = 0x08074b50,
91 #endif
92 };
93
94 #define ZIP_HEADER_LEN 26
95
96 typedef union {
97         uint8_t raw[ZIP_HEADER_LEN];
98         struct {
99                 uint16_t version;               /* 0-1 */
100                 uint16_t zip_flags;             /* 2-3 */
101                 uint16_t method;                /* 4-5 */
102                 uint16_t modtime;               /* 6-7 */
103                 uint16_t moddate;               /* 8-9 */
104                 uint32_t crc32 PACKED;          /* 10-13 */
105                 uint32_t cmpsize PACKED;        /* 14-17 */
106                 uint32_t ucmpsize PACKED;       /* 18-21 */
107                 uint16_t filename_len;          /* 22-23 */
108                 uint16_t extra_len;             /* 24-25 */
109                 /* filename follows (not NUL terminated) */
110                 /* extra field follows */
111                 /* data follows */
112         } fmt PACKED;
113 } zip_header_t; /* PACKED - gcc 4.2.1 doesn't like it (spews warning) */
114
115 #define FIX_ENDIANNESS_ZIP(zip) \
116 do { if (BB_BIG_ENDIAN) { \
117         (zip).fmt.method        = SWAP_LE16((zip).fmt.method      ); \
118         (zip).fmt.crc32         = SWAP_LE32((zip).fmt.crc32       ); \
119         (zip).fmt.cmpsize       = SWAP_LE32((zip).fmt.cmpsize     ); \
120         (zip).fmt.ucmpsize      = SWAP_LE32((zip).fmt.ucmpsize    ); \
121         (zip).fmt.filename_len  = SWAP_LE16((zip).fmt.filename_len); \
122         (zip).fmt.extra_len     = SWAP_LE16((zip).fmt.extra_len   ); \
123 }} while (0)
124
125 #define CDF_HEADER_LEN 42
126
127 typedef union {
128         uint8_t raw[CDF_HEADER_LEN];
129         struct {
130                 /* uint32_t signature; 50 4b 01 02 */
131                 uint16_t version_made_by;       /* 0-1 */
132                 uint16_t version_needed;        /* 2-3 */
133                 uint16_t cdf_flags;             /* 4-5 */
134                 uint16_t method;                /* 6-7 */
135                 uint16_t modtime;               /* 8-9 */
136                 uint16_t moddate;               /* 10-11 */
137                 uint32_t crc32;                 /* 12-15 */
138                 uint32_t cmpsize;               /* 16-19 */
139                 uint32_t ucmpsize;              /* 20-23 */
140                 uint16_t filename_len;          /* 24-25 */
141                 uint16_t extra_len;             /* 26-27 */
142                 uint16_t file_comment_length;   /* 28-29 */
143                 uint16_t disk_number_start;     /* 30-31 */
144                 uint16_t internal_attributes;   /* 32-33 */
145                 uint32_t external_attributes PACKED; /* 34-37 */
146                 uint32_t relative_offset_of_local_header PACKED; /* 38-41 */
147                 /* filename follows (not NUL terminated) */
148                 /* extra field follows */
149                 /* file comment follows */
150         } fmt PACKED;
151 } cdf_header_t;
152
153 #define FIX_ENDIANNESS_CDF(cdf) \
154 do { if (BB_BIG_ENDIAN) { \
155         (cdf).fmt.version_made_by = SWAP_LE16((cdf).fmt.version_made_by); \
156         (cdf).fmt.version_needed = SWAP_LE16((cdf).fmt.version_needed); \
157         (cdf).fmt.method        = SWAP_LE16((cdf).fmt.method      ); \
158         (cdf).fmt.modtime       = SWAP_LE16((cdf).fmt.modtime     ); \
159         (cdf).fmt.moddate       = SWAP_LE16((cdf).fmt.moddate     ); \
160         (cdf).fmt.crc32         = SWAP_LE32((cdf).fmt.crc32       ); \
161         (cdf).fmt.cmpsize       = SWAP_LE32((cdf).fmt.cmpsize     ); \
162         (cdf).fmt.ucmpsize      = SWAP_LE32((cdf).fmt.ucmpsize    ); \
163         (cdf).fmt.filename_len  = SWAP_LE16((cdf).fmt.filename_len); \
164         (cdf).fmt.extra_len     = SWAP_LE16((cdf).fmt.extra_len   ); \
165         (cdf).fmt.file_comment_length = SWAP_LE16((cdf).fmt.file_comment_length); \
166         (cdf).fmt.external_attributes = SWAP_LE32((cdf).fmt.external_attributes); \
167 }} while (0)
168
169 #define CDE_LEN 16
170
171 typedef union {
172         uint8_t raw[CDE_LEN];
173         struct {
174                 /* uint32_t signature; 50 4b 05 06 */
175                 uint16_t this_disk_no;
176                 uint16_t disk_with_cdf_no;
177                 uint16_t cdf_entries_on_this_disk;
178                 uint16_t cdf_entries_total;
179                 uint32_t cdf_size;
180                 uint32_t cdf_offset;
181                 /* uint16_t archive_comment_length; */
182                 /* archive comment follows */
183         } fmt PACKED;
184 } cde_t;
185
186 #define FIX_ENDIANNESS_CDE(cde) \
187 do { if (BB_BIG_ENDIAN) { \
188         (cde).fmt.cdf_offset = SWAP_LE32((cde).fmt.cdf_offset); \
189 }} while (0)
190
191 struct BUG {
192         /* Check the offset of the last element, not the length.  This leniency
193          * allows for poor packing, whereby the overall struct may be too long,
194          * even though the elements are all in the right place.
195          */
196         char BUG_zip_header_must_be_26_bytes[
197                 offsetof(zip_header_t, fmt.extra_len) + 2
198                         == ZIP_HEADER_LEN ? 1 : -1];
199         char BUG_cdf_header_must_be_42_bytes[
200                 offsetof(cdf_header_t, fmt.relative_offset_of_local_header) + 4
201                         == CDF_HEADER_LEN ? 1 : -1];
202         char BUG_cde_must_be_16_bytes[
203                 sizeof(cde_t) == CDE_LEN ? 1 : -1];
204 };
205
206
207 enum { zip_fd = 3 };
208
209
210 /* This value means that we failed to find CDF */
211 #define BAD_CDF_OFFSET ((uint32_t)0xffffffff)
212
213 #if !ENABLE_FEATURE_UNZIP_CDF
214
215 # define find_cdf_offset() BAD_CDF_OFFSET
216
217 #else
218 /* Seen in the wild:
219  * Self-extracting PRO2K3XP_32.exe contains 19078464 byte zip archive,
220  * where CDE was nearly 48 kbytes before EOF.
221  * (Surprisingly, it also apparently has *another* CDE structure
222  * closer to the end, with bogus cdf_offset).
223  * To make extraction work, bumped PEEK_FROM_END from 16k to 64k.
224  */
225 #define PEEK_FROM_END (64*1024)
226 /* NB: does not preserve file position! */
227 static uint32_t find_cdf_offset(void)
228 {
229         cde_t cde;
230         unsigned char *buf;
231         unsigned char *p;
232         off_t end;
233         uint32_t found;
234
235         end = lseek(zip_fd, 0, SEEK_END);
236         if (end == (off_t) -1)
237                 return BAD_CDF_OFFSET;
238
239         end -= PEEK_FROM_END;
240         if (end < 0)
241                 end = 0;
242
243         dbg("Looking for cdf_offset starting from 0x%"OFF_FMT"x", end);
244         xlseek(zip_fd, end, SEEK_SET);
245         buf = xzalloc(PEEK_FROM_END);
246         full_read(zip_fd, buf, PEEK_FROM_END);
247
248         found = BAD_CDF_OFFSET;
249         p = buf;
250         while (p <= buf + PEEK_FROM_END - CDE_LEN - 4) {
251                 if (*p != 'P') {
252                         p++;
253                         continue;
254                 }
255                 if (*++p != 'K')
256                         continue;
257                 if (*++p != 5)
258                         continue;
259                 if (*++p != 6)
260                         continue;
261                 /* we found CDE! */
262                 memcpy(cde.raw, p + 1, CDE_LEN);
263                 FIX_ENDIANNESS_CDE(cde);
264                 /*
265                  * I've seen .ZIP files with seemingly valid CDEs
266                  * where cdf_offset points past EOF - ??
267                  * This check ignores such CDEs:
268                  */
269                 if (cde.fmt.cdf_offset < end + (p - buf)) {
270                         found = cde.fmt.cdf_offset;
271                         dbg("Possible cdf_offset:0x%x at 0x%"OFF_FMT"x",
272                                 (unsigned)found, end + (p-3 - buf));
273                         dbg("  cdf_offset+cdf_size:0x%x",
274                                 (unsigned)(found + SWAP_LE32(cde.fmt.cdf_size)));
275                         /*
276                          * We do not "break" here because only the last CDE is valid.
277                          * I've seen a .zip archive which contained a .zip file,
278                          * uncompressed, and taking the first CDE was using
279                          * the CDE inside that file!
280                          */
281                 }
282         }
283         free(buf);
284         dbg("Found cdf_offset:0x%x", (unsigned)found);
285         return found;
286 };
287
288 static uint32_t read_next_cdf(uint32_t cdf_offset, cdf_header_t *cdf)
289 {
290         uint32_t magic;
291
292         if (cdf_offset == BAD_CDF_OFFSET)
293                 return cdf_offset;
294
295         dbg("Reading CDF at 0x%x", (unsigned)cdf_offset);
296         xlseek(zip_fd, cdf_offset, SEEK_SET);
297         xread(zip_fd, &magic, 4);
298         /* Central Directory End? Assume CDF has ended.
299          * (more correct method is to use cde.cdf_entries_total counter)
300          */
301         if (magic == ZIP_CDE_MAGIC) {
302                 dbg("got ZIP_CDE_MAGIC");
303                 return 0; /* EOF */
304         }
305         xread(zip_fd, cdf->raw, CDF_HEADER_LEN);
306
307         FIX_ENDIANNESS_CDF(*cdf);
308         dbg("  filename_len:%u extra_len:%u file_comment_length:%u",
309                 (unsigned)cdf->fmt.filename_len,
310                 (unsigned)cdf->fmt.extra_len,
311                 (unsigned)cdf->fmt.file_comment_length
312         );
313         cdf_offset += 4 + CDF_HEADER_LEN
314                 + cdf->fmt.filename_len
315                 + cdf->fmt.extra_len
316                 + cdf->fmt.file_comment_length;
317
318         return cdf_offset;
319 };
320 #endif
321
322 static void die_if_bad_fnamesize(unsigned sz)
323 {
324         if (sz > 0xfff) /* more than 4k?! no funny business please */
325                 bb_error_msg_and_die("bad archive");
326 }
327
328 static void unzip_skip(off_t skip)
329 {
330         if (skip != 0)
331                 if (lseek(zip_fd, skip, SEEK_CUR) == (off_t)-1)
332                         bb_copyfd_exact_size(zip_fd, -1, skip);
333 }
334
335 static void unzip_create_leading_dirs(const char *fn)
336 {
337         /* Create all leading directories */
338         char *name = xstrdup(fn);
339         if (bb_make_directory(dirname(name), 0777, FILEUTILS_RECUR)) {
340                 xfunc_die(); /* bb_make_directory is noisy */
341         }
342         free(name);
343 }
344
345 #if ENABLE_FEATURE_UNZIP_CDF
346 static void unzip_extract_symlink(zip_header_t *zip, const char *dst_fn)
347 {
348         char *target;
349
350         die_if_bad_fnamesize(zip->fmt.ucmpsize);
351
352         if (zip->fmt.method == 0) {
353                 /* Method 0 - stored (not compressed) */
354                 target = xzalloc(zip->fmt.ucmpsize + 1);
355                 xread(zip_fd, target, zip->fmt.ucmpsize);
356         } else {
357 #if 1
358                 bb_error_msg_and_die("compressed symlink is not supported");
359 #else
360                 transformer_state_t xstate;
361                 init_transformer_state(&xstate);
362                 xstate.mem_output_size_max = zip->fmt.ucmpsize;
363                 /* ...unpack... */
364                 if (!xstate.mem_output_buf)
365                         WTF();
366                 target = xstate.mem_output_buf;
367                 target = xrealloc(target, xstate.mem_output_size + 1);
368                 target[xstate.mem_output_size] = '\0';
369 #endif
370         }
371         if (!unsafe_symlink_target(target)) {
372 //TODO: libbb candidate
373                 if (symlink(target, dst_fn)) {
374                         /* shared message */
375                         bb_perror_msg_and_die("can't create %slink '%s' to '%s'",
376                                 "sym", dst_fn, target
377                         );
378                 }
379         }
380         free(target);
381 }
382 #endif
383
384 static void unzip_extract(zip_header_t *zip, int dst_fd)
385 {
386         transformer_state_t xstate;
387
388         if (zip->fmt.method == 0) {
389                 /* Method 0 - stored (not compressed) */
390                 off_t size = zip->fmt.ucmpsize;
391                 if (size)
392                         bb_copyfd_exact_size(zip_fd, dst_fd, size);
393                 return;
394         }
395
396         init_transformer_state(&xstate);
397         xstate.bytes_in = zip->fmt.cmpsize;
398         xstate.src_fd = zip_fd;
399         xstate.dst_fd = dst_fd;
400         if (zip->fmt.method == 8) {
401                 /* Method 8 - inflate */
402                 if (inflate_unzip(&xstate) < 0)
403                         bb_error_msg_and_die("inflate error");
404                 /* Validate decompression - crc */
405                 if (zip->fmt.crc32 != (xstate.crc32 ^ 0xffffffffL)) {
406                         bb_error_msg_and_die("crc error");
407                 }
408         }
409 #if ENABLE_FEATURE_UNZIP_BZIP2
410         else if (zip->fmt.method == 12) {
411                 /* Tested. Unpacker reads too much, but we use CDF
412                  * and will seek to the correct beginning of next file.
413                  */
414                 xstate.bytes_out = unpack_bz2_stream(&xstate);
415                 if (xstate.bytes_out < 0)
416                         bb_error_msg_and_die("inflate error");
417         }
418 #endif
419 #if ENABLE_FEATURE_UNZIP_LZMA
420         else if (zip->fmt.method == 14) {
421                 /* Not tested yet */
422                 xstate.bytes_out = unpack_lzma_stream(&xstate);
423                 if (xstate.bytes_out < 0)
424                         bb_error_msg_and_die("inflate error");
425         }
426 #endif
427 #if ENABLE_FEATURE_UNZIP_XZ
428         else if (zip->fmt.method == 95) {
429                 /* Not tested yet */
430                 xstate.bytes_out = unpack_xz_stream(&xstate);
431                 if (xstate.bytes_out < 0)
432                         bb_error_msg_and_die("inflate error");
433         }
434 #endif
435         else {
436                 bb_error_msg_and_die("unsupported method %u", zip->fmt.method);
437         }
438
439         /* Validate decompression - size */
440         if (zip->fmt.ucmpsize != xstate.bytes_out) {
441                 /* Don't die. Who knows, maybe len calculation
442                  * was botched somewhere. After all, crc matched! */
443                 bb_error_msg("bad length");
444         }
445 }
446
447 static void my_fgets80(char *buf80)
448 {
449         fflush_all();
450         if (!fgets(buf80, 80, stdin)) {
451                 bb_perror_msg_and_die("can't read standard input");
452         }
453 }
454
455 static int get_lstat_mode(const char *dst_fn)
456 {
457         struct stat stat_buf;
458         if (lstat(dst_fn, &stat_buf) == -1) {
459                 if (errno != ENOENT) {
460                         bb_perror_msg_and_die("can't stat '%s'", dst_fn);
461                 }
462                 /* File does not exist */
463                 return -1;
464         }
465         return stat_buf.st_mode;
466 }
467
468 int unzip_main(int argc, char **argv) MAIN_EXTERNALLY_VISIBLE;
469 int unzip_main(int argc, char **argv)
470 {
471         enum {
472                 OPT_l = (1 << 0),
473                 OPT_x = (1 << 1),
474                 OPT_j = (1 << 2),
475         };
476         unsigned opts;
477         smallint quiet = 0;
478         IF_NOT_FEATURE_UNZIP_CDF(const) smallint verbose = 0;
479         enum { O_PROMPT, O_NEVER, O_ALWAYS };
480         smallint overwrite = O_PROMPT;
481         uint32_t cdf_offset;
482         unsigned long total_usize;
483         unsigned long total_size;
484         unsigned total_entries;
485         int dst_fd = -1;
486         char *src_fn = NULL;
487         char *dst_fn = NULL;
488         llist_t *zaccept = NULL;
489         llist_t *zreject = NULL;
490         char *base_dir = NULL;
491         int i;
492         char key_buf[80]; /* must match size used by my_fgets80 */
493
494 /* -q, -l and -v: UnZip 5.52 of 28 February 2005, by Info-ZIP:
495  *
496  * # /usr/bin/unzip -qq -v decompress_unlzma.i.zip
497  *   204372  Defl:N    35278  83%  09-06-09 14:23  0d056252  decompress_unlzma.i
498  * # /usr/bin/unzip -q -v decompress_unlzma.i.zip
499  *  Length   Method    Size  Ratio   Date   Time   CRC-32    Name
500  * --------  ------  ------- -----   ----   ----   ------    ----
501  *   204372  Defl:N    35278  83%  09-06-09 14:23  0d056252  decompress_unlzma.i
502  * --------          -------  ---                            -------
503  *   204372            35278  83%                            1 file
504  * # /usr/bin/unzip -v decompress_unlzma.i.zip
505  * Archive:  decompress_unlzma.i.zip
506  *  Length   Method    Size  Ratio   Date   Time   CRC-32    Name
507  * --------  ------  ------- -----   ----   ----   ------    ----
508  *   204372  Defl:N    35278  83%  09-06-09 14:23  0d056252  decompress_unlzma.i
509  * --------          -------  ---                            -------
510  *   204372            35278  83%                            1 file
511  * # unzip -v decompress_unlzma.i.zip
512  * Archive:  decompress_unlzma.i.zip
513  *   Length     Date   Time    Name
514  *  --------    ----   ----    ----
515  *    204372  09-06-09 14:23   decompress_unlzma.i
516  *  --------                   -------
517  *    204372                   1 files
518  * # /usr/bin/unzip -l -qq decompress_unlzma.i.zip
519  *    204372  09-06-09 14:23   decompress_unlzma.i
520  * # /usr/bin/unzip -l -q decompress_unlzma.i.zip
521  *   Length     Date   Time    Name
522  *  --------    ----   ----    ----
523  *    204372  09-06-09 14:23   decompress_unlzma.i
524  *  --------                   -------
525  *    204372                   1 file
526  * # /usr/bin/unzip -l decompress_unlzma.i.zip
527  * Archive:  decompress_unlzma.i.zip
528  *   Length     Date   Time    Name
529  *  --------    ----   ----    ----
530  *    204372  09-06-09 14:23   decompress_unlzma.i
531  *  --------                   -------
532  *    204372                   1 file
533  */
534
535         opts = 0;
536         /* '-' makes getopt return 1 for non-options */
537         while ((i = getopt(argc, argv, "-d:lnopqxjv")) != -1) {
538                 switch (i) {
539                 case 'd':  /* Extract to base directory */
540                         base_dir = optarg;
541                         break;
542
543                 case 'l': /* List */
544                         opts |= OPT_l;
545                         break;
546
547                 case 'n': /* Never overwrite existing files */
548                         overwrite = O_NEVER;
549                         break;
550
551                 case 'o': /* Always overwrite existing files */
552                         overwrite = O_ALWAYS;
553                         break;
554
555                 case 'p': /* Extract files to stdout and fall through to set verbosity */
556                         dst_fd = STDOUT_FILENO;
557
558                 case 'q': /* Be quiet */
559                         quiet++;
560                         break;
561
562                 case 'v': /* Verbose list */
563                         IF_FEATURE_UNZIP_CDF(verbose++;)
564                         opts |= OPT_l;
565                         break;
566
567                 case 'x':
568                         opts |= OPT_x;
569                         break;
570
571                 case 'j':
572                         opts |= OPT_j;
573                         break;
574
575                 case 1:
576                         if (!src_fn) {
577                                 /* The zip file */
578                                 /* +5: space for ".zip" and NUL */
579                                 src_fn = xmalloc(strlen(optarg) + 5);
580                                 strcpy(src_fn, optarg);
581                         } else if (!(opts & OPT_x)) {
582                                 /* Include files */
583                                 llist_add_to(&zaccept, optarg);
584                         } else {
585                                 /* Exclude files */
586                                 llist_add_to(&zreject, optarg);
587                         }
588                         break;
589
590                 default:
591                         bb_show_usage();
592                 }
593         }
594
595 #ifndef __GLIBC__
596         /*
597          * This code is needed for non-GNU getopt
598          * which doesn't understand "-" in option string.
599          * The -x option won't work properly in this case:
600          * "unzip a.zip q -x w e" will be interpreted as
601          * "unzip a.zip q w e -x" = "unzip a.zip q w e"
602          */
603         argv += optind;
604         if (argv[0]) {
605                 /* +5: space for ".zip" and NUL */
606                 src_fn = xmalloc(strlen(argv[0]) + 5);
607                 strcpy(src_fn, argv[0]);
608                 while (*++argv)
609                         llist_add_to(&zaccept, *argv);
610         }
611 #endif
612
613         if (!src_fn) {
614                 bb_show_usage();
615         }
616
617         /* Open input file */
618         if (LONE_DASH(src_fn)) {
619                 xdup2(STDIN_FILENO, zip_fd);
620                 /* Cannot use prompt mode since zip data is arriving on STDIN */
621                 if (overwrite == O_PROMPT)
622                         overwrite = O_NEVER;
623         } else {
624                 static const char extn[][5] ALIGN1 = { ".zip", ".ZIP" };
625                 char *ext = src_fn + strlen(src_fn);
626                 int src_fd;
627
628                 i = 0;
629                 for (;;) {
630                         src_fd = open(src_fn, O_RDONLY);
631                         if (src_fd >= 0)
632                                 break;
633                         if (++i > 2) {
634                                 *ext = '\0';
635                                 bb_error_msg_and_die("can't open %s[.zip]", src_fn);
636                         }
637                         strcpy(ext, extn[i - 1]);
638                 }
639                 xmove_fd(src_fd, zip_fd);
640         }
641
642         /* Change dir if necessary */
643         if (base_dir)
644                 xchdir(base_dir);
645
646         if (quiet <= 1) { /* not -qq */
647                 if (quiet == 0)
648                         printf("Archive:  %s\n", src_fn);
649                 if (opts & OPT_l) {
650                         puts(verbose ?
651                                 " Length   Method    Size  Cmpr    Date    Time   CRC-32   Name\n"
652                                 "--------  ------  ------- ---- ---------- ----- --------  ----"
653                                 :
654                                 "  Length      Date    Time    Name\n"
655                                 "---------  ---------- -----   ----"
656                                 );
657                 }
658         }
659
660 /* Example of an archive with one 0-byte long file named 'z'
661  * created by Zip 2.31 on Unix:
662  * 0000 [50 4b]03 04 0a 00 00 00 00 00 42 1a b8 3c 00 00 |PK........B..<..|
663  *       sig........ vneed flags compr mtime mdate crc32>
664  * 0010  00 00 00 00 00 00 00 00 00 00 01 00 15 00 7a 55 |..............zU|
665  *      >..... csize...... usize...... fnlen exlen fn ex>
666  * 0020  54 09 00 03 cc d3 f9 4b cc d3 f9 4b 55 78 04 00 |T......K...KUx..|
667  *      >tra_field......................................
668  * 0030  00 00 00 00[50 4b]01 02 17 03 0a 00 00 00 00 00 |....PK..........|
669  *       ........... sig........ vmade vneed flags compr
670  * 0040  42 1a b8 3c 00 00 00 00 00 00 00 00 00 00 00 00 |B..<............|
671  *       mtime mdate crc32...... csize...... usize......
672  * 0050  01 00 0d 00 00 00 00 00 00 00 00 00 a4 81 00 00 |................|
673  *       fnlen exlen clen. dnum. iattr eattr...... relofs> (eattr = rw-r--r--)
674  * 0060  00 00 7a 55 54 05 00 03 cc d3 f9 4b 55 78 00 00 |..zUT......KUx..|
675  *      >..... fn extra_field...........................
676  * 0070 [50 4b]05 06 00 00 00 00 01 00 01 00 3c 00 00 00 |PK..........<...|
677  * 0080  34 00 00 00 00 00                               |4.....|
678  */
679         total_usize = 0;
680         total_size = 0;
681         total_entries = 0;
682         cdf_offset = find_cdf_offset(); /* try to seek to the end, find CDE and CDF start */
683         while (1) {
684                 zip_header_t zip;
685                 mode_t dir_mode = 0777;
686 #if ENABLE_FEATURE_UNZIP_CDF
687                 mode_t file_mode = 0666;
688 #endif
689
690                 if (!ENABLE_FEATURE_UNZIP_CDF || cdf_offset == BAD_CDF_OFFSET) {
691                         /* Normally happens when input is unseekable.
692                          *
693                          * Valid ZIP file has Central Directory at the end
694                          * with central directory file headers (CDFs).
695                          * After it, there is a Central Directory End structure.
696                          * CDFs identify what files are in the ZIP and where
697                          * they are located. This allows ZIP readers to load
698                          * the list of files without reading the entire ZIP archive.
699                          * ZIP files may be appended to, only files specified in
700                          * the CD are valid. Scanning for local file headers is
701                          * not a correct algorithm.
702                          *
703                          * We try to do the above, and resort to "linear" reading
704                          * of ZIP file only if seek failed or CDE wasn't found.
705                          */
706                         uint32_t magic;
707
708                         /* Check magic number */
709                         xread(zip_fd, &magic, 4);
710                         /* CDF item? Assume there are no more files, exit */
711                         if (magic == ZIP_CDF_MAGIC) {
712                                 dbg("got ZIP_CDF_MAGIC");
713                                 break;
714                         }
715                         /* Data descriptor? It was a streaming file, go on */
716                         if (magic == ZIP_DD_MAGIC) {
717                                 dbg("got ZIP_DD_MAGIC");
718                                 /* skip over duplicate crc32, cmpsize and ucmpsize */
719                                 unzip_skip(3 * 4);
720                                 continue;
721                         }
722                         if (magic != ZIP_FILEHEADER_MAGIC)
723                                 bb_error_msg_and_die("invalid zip magic %08X", (int)magic);
724                         dbg("got ZIP_FILEHEADER_MAGIC");
725
726                         xread(zip_fd, zip.raw, ZIP_HEADER_LEN);
727                         FIX_ENDIANNESS_ZIP(zip);
728                         if (zip.fmt.zip_flags & SWAP_LE16(0x0008)) {
729                                 bb_error_msg_and_die("zip flag %s is not supported",
730                                         "8 (streaming)");
731                         }
732                 }
733 #if ENABLE_FEATURE_UNZIP_CDF
734                 else {
735                         /* cdf_offset is valid (and we know the file is seekable) */
736                         cdf_header_t cdf;
737                         cdf_offset = read_next_cdf(cdf_offset, &cdf);
738                         if (cdf_offset == 0) /* EOF? */
739                                 break;
740 # if 1
741                         xlseek(zip_fd,
742                                 SWAP_LE32(cdf.fmt.relative_offset_of_local_header) + 4,
743                                 SEEK_SET);
744                         xread(zip_fd, zip.raw, ZIP_HEADER_LEN);
745                         FIX_ENDIANNESS_ZIP(zip);
746                         if (zip.fmt.zip_flags & SWAP_LE16(0x0008)) {
747                                 /* 0x0008 - streaming. [u]cmpsize can be reliably gotten
748                                  * only from Central Directory.
749                                  */
750                                 zip.fmt.crc32    = cdf.fmt.crc32;
751                                 zip.fmt.cmpsize  = cdf.fmt.cmpsize;
752                                 zip.fmt.ucmpsize = cdf.fmt.ucmpsize;
753                         }
754 // Seen in some zipfiles: central directory 9 byte extra field contains
755 // a subfield with ID 0x5455 and 5 data bytes, which is a Unix-style UTC mtime.
756 // Local header version:
757 //  u16 0x5455 ("UT")
758 //  u16 size (1 + 4 * n)
759 //  u8  flags: bit 0:mtime is present, bit 1:atime is present, bit 2:ctime is present
760 //  u32 mtime
761 //  u32 atime
762 //  u32 ctime
763 // Central header version:
764 //  u16 0x5455 ("UT")
765 //  u16 size (5 (or 1?))
766 //  u8  flags: bit 0:mtime is present, bit 1:atime is present, bit 2:ctime is present
767 //  u32 mtime (CDF does not store atime/ctime)
768 # else
769                         /* CDF has the same data as local header, no need to read the latter...
770                          * ...not really. An archive was seen with cdf.extra_len == 6 but
771                          * zip.extra_len == 0.
772                          */
773                         memcpy(&zip.fmt.version,
774                                 &cdf.fmt.version_needed, ZIP_HEADER_LEN);
775                         xlseek(zip_fd,
776                                 SWAP_LE32(cdf.fmt.relative_offset_of_local_header) + 4 + ZIP_HEADER_LEN,
777                                 SEEK_SET);
778 # endif
779                         if ((cdf.fmt.version_made_by >> 8) == 3) {
780                                 /* This archive is created on Unix */
781                                 dir_mode = file_mode = (cdf.fmt.external_attributes >> 16);
782                         }
783                 }
784 #endif
785
786                 if (zip.fmt.zip_flags & SWAP_LE16(0x0001)) {
787                         /* 0x0001 - encrypted */
788                         bb_error_msg_and_die("zip flag %s is not supported",
789                                         "1 (encryption)");
790                 }
791                 dbg("File cmpsize:0x%x extra_len:0x%x ucmpsize:0x%x",
792                         (unsigned)zip.fmt.cmpsize,
793                         (unsigned)zip.fmt.extra_len,
794                         (unsigned)zip.fmt.ucmpsize
795                 );
796
797                 /* Read filename */
798                 free(dst_fn);
799                 die_if_bad_fnamesize(zip.fmt.filename_len);
800                 dst_fn = xzalloc(zip.fmt.filename_len + 1);
801                 xread(zip_fd, dst_fn, zip.fmt.filename_len);
802                 /* Skip extra header bytes */
803                 unzip_skip(zip.fmt.extra_len);
804
805                 /* Guard against "/abspath", "/../" and similar attacks */
806                 overlapping_strcpy(dst_fn, strip_unsafe_prefix(dst_fn));
807
808                 if (opts & OPT_j) /* Strip paths? */
809                         overlapping_strcpy(dst_fn, bb_basename(dst_fn));
810
811                 /* Did this strip everything ("DIR/" case)? Then skip */
812                 if (!dst_fn[0])
813                         goto skip_cmpsize;
814
815                 /* Filter zip entries */
816                 if (find_list_entry(zreject, dst_fn)
817                  || (zaccept && !find_list_entry(zaccept, dst_fn))
818                 ) { /* Skip entry */
819                         goto skip_cmpsize;
820                 }
821
822                 if (opts & OPT_l) {
823                         /* List entry */
824                         char dtbuf[sizeof("mm-dd-yyyy hh:mm")];
825                         sprintf(dtbuf, "%02u-%02u-%04u %02u:%02u",
826                                 (zip.fmt.moddate >> 5) & 0xf,  // mm: 0x01e0
827                                 (zip.fmt.moddate)      & 0x1f, // dd: 0x001f
828                                 (zip.fmt.moddate >> 9) + 1980, // yy: 0xfe00
829                                 (zip.fmt.modtime >> 11),       // hh: 0xf800
830                                 (zip.fmt.modtime >> 5) & 0x3f  // mm: 0x07e0
831                                 // seconds/2 not shown, encoded in -- 0x001f
832                         );
833                         if (!verbose) {
834                                 //      "  Length      Date    Time    Name\n"
835                                 //      "---------  ---------- -----   ----"
836                                 printf(       "%9u  " "%s   "         "%s\n",
837                                         (unsigned)zip.fmt.ucmpsize,
838                                         dtbuf,
839                                         dst_fn);
840                         } else {
841                                 char method6[7];
842                                 unsigned long percents;
843
844                                 sprintf(method6, "%6u", zip.fmt.method);
845                                 if (zip.fmt.method == 0) {
846                                         strcpy(method6, "Stored");
847                                 }
848                                 if (zip.fmt.method == 8) {
849                                         strcpy(method6, "Defl:N");
850                                         /* normal, maximum, fast, superfast */
851                                         IF_DESKTOP(method6[5] = "NXFS"[(zip.fmt.zip_flags >> 1) & 3];)
852                                 }
853                                 percents = zip.fmt.ucmpsize - zip.fmt.cmpsize;
854                                 if ((int32_t)percents < 0)
855                                         percents = 0; /* happens if ucmpsize < cmpsize */
856                                 percents = percents * 100;
857                                 if (zip.fmt.ucmpsize)
858                                         percents /= zip.fmt.ucmpsize;
859                                 //      " Length   Method    Size  Cmpr    Date    Time   CRC-32   Name\n"
860                                 //      "--------  ------  ------- ---- ---------- ----- --------  ----"
861                                 printf(      "%8u  %s"        "%9u%4u%% " "%s "         "%08x  "  "%s\n",
862                                         (unsigned)zip.fmt.ucmpsize,
863                                         method6,
864                                         (unsigned)zip.fmt.cmpsize,
865                                         (unsigned)percents,
866                                         dtbuf,
867                                         zip.fmt.crc32,
868                                         dst_fn);
869                                 total_size += zip.fmt.cmpsize;
870                         }
871                         total_usize += zip.fmt.ucmpsize;
872                         goto skip_cmpsize;
873                 }
874
875                 if (dst_fd == STDOUT_FILENO) {
876                         /* Extracting to STDOUT */
877                         goto do_extract;
878                 }
879                 if (last_char_is(dst_fn, '/')) {
880                         int mode;
881
882                         /* Extract directory */
883                         mode = get_lstat_mode(dst_fn);
884                         if (mode == -1) { /* ENOENT */
885                                 if (!quiet) {
886                                         printf("   creating: %s\n", dst_fn);
887                                 }
888                                 unzip_create_leading_dirs(dst_fn);
889                                 if (bb_make_directory(dst_fn, dir_mode, FILEUTILS_IGNORE_CHMOD_ERR)) {
890                                         xfunc_die();
891                                 }
892                         } else {
893                                 if (!S_ISDIR(mode)) {
894                                         bb_error_msg_and_die("'%s' exists but is not a %s",
895                                                 dst_fn, "directory");
896                                 }
897                         }
898                         goto skip_cmpsize;
899                 }
900  check_file:
901                 /* Does target file already exist? */
902                 {
903                         int mode = get_lstat_mode(dst_fn);
904                         if (mode == -1) {
905                                 /* ENOENT: does not exist */
906                                 goto do_open_and_extract;
907                         }
908                         if (overwrite == O_NEVER) {
909                                 goto skip_cmpsize;
910                         }
911                         if (!S_ISREG(mode)) {
912  fishy:
913                                 bb_error_msg_and_die("'%s' exists but is not a %s",
914                                         dst_fn, "regular file");
915                         }
916                         if (overwrite == O_ALWAYS) {
917                                 goto do_open_and_extract;
918                         }
919                         printf("replace %s? [y]es, [n]o, [A]ll, [N]one, [r]ename: ", dst_fn);
920                         my_fgets80(key_buf);
921                         /* User input could take a long time. Is it still a regular file? */
922                         mode = get_lstat_mode(dst_fn);
923                         if (!S_ISREG(mode))
924                                 goto fishy;
925                 }
926
927                 /* Extract (or skip) it */
928                 switch (key_buf[0]) {
929                 case 'A':
930                         overwrite = O_ALWAYS;
931                 case 'y': /* Open file and fall into unzip */
932  do_open_and_extract:
933                         unzip_create_leading_dirs(dst_fn);
934 #if ENABLE_FEATURE_UNZIP_CDF
935                         dst_fd = -1;
936                         if (!S_ISLNK(file_mode)) {
937                                 dst_fd = xopen3(dst_fn,
938                                         O_WRONLY | O_CREAT | O_TRUNC | O_NOFOLLOW,
939                                         file_mode);
940                         }
941 #else
942                         /* O_NOFOLLOW defends against symlink attacks */
943                         dst_fd = xopen(dst_fn, O_WRONLY | O_CREAT | O_TRUNC | O_NOFOLLOW);
944 #endif
945  do_extract:
946                         if (!quiet) {
947                                 printf(/* zip.fmt.method == 0
948                                         ? " extracting: %s\n"
949                                         : */ "  inflating: %s\n", dst_fn);
950                         }
951 #if ENABLE_FEATURE_UNZIP_CDF
952                         if (S_ISLNK(file_mode)) {
953                                 if (dst_fd != STDOUT_FILENO) /* not -p? */
954                                         unzip_extract_symlink(&zip, dst_fn);
955                         } else
956 #endif
957                         {
958                                 unzip_extract(&zip, dst_fd);
959                                 if (dst_fd != STDOUT_FILENO) {
960                                         /* closing STDOUT is potentially bad for future business */
961                                         close(dst_fd);
962                                 }
963                         }
964                         break;
965
966                 case 'N':
967                         overwrite = O_NEVER;
968                 case 'n': /* Skip entry data */
969  skip_cmpsize:
970                         unzip_skip(zip.fmt.cmpsize);
971                         break;
972
973                 case 'r':
974                         /* Prompt for new name */
975                         printf("new name: ");
976                         my_fgets80(key_buf);
977                         free(dst_fn);
978                         dst_fn = xstrdup(key_buf);
979                         chomp(dst_fn);
980                         goto check_file;
981
982                 default:
983                         printf("error: invalid response [%c]\n", (char)key_buf[0]);
984                         goto check_file;
985                 }
986
987                 total_entries++;
988         }
989
990         if ((opts & OPT_l) && quiet <= 1) {
991                 if (!verbose) {
992                         //      "  Length      Date    Time    Name\n"
993                         //      "---------  ---------- -----   ----"
994                         printf( " --------%21s"               "-------\n"
995                                      "%9lu%21s"               "%u files\n",
996                                 "",
997                                 total_usize, "", total_entries);
998                 } else {
999                         unsigned long percents = total_usize - total_size;
1000                         if ((long)percents < 0)
1001                                 percents = 0; /* happens if usize < size */
1002                         percents = percents * 100;
1003                         if (total_usize)
1004                                 percents /= total_usize;
1005                         //      " Length   Method    Size  Cmpr    Date    Time   CRC-32   Name\n"
1006                         //      "--------  ------  ------- ---- ---------- ----- --------  ----"
1007                         printf( "--------          ------- ----%28s"                      "----\n"
1008                                 "%8lu"              "%17lu%4u%%%28s"                      "%u files\n",
1009                                 "",
1010                                 total_usize, total_size, (unsigned)percents, "",
1011                                 total_entries);
1012                 }
1013         }
1014
1015         return 0;
1016 }